As we announced last week, the KDE Project has released kdelibs-2.1.2 to address a security issue and fix some bugs. Besides fixing the KDEsu security exploit, particularly joyful to many of you who use Konqueror will be the fix of the "protocol for http://x.y.z died unexpectedly" bug. "Read more" for the full text of the announcement, including a list of changes.

DATELINE APRIL 30, 2001

FOR IMMEDIATE RELEASE

SECURITY: New KDE Libraries Released

KDE Adds Security and Bug Fixes to Core Libraries

April 30, 2001 (The INTERNET).
The KDE
Project today announced the release of kdelibs 2.1.2,
a security and bugfix release of the core KDE libraries. The other
core KDE packages, including kdebase, have not been updated. The KDE Project
recommends that all KDE users upgrade to kdelibs 2.1.2 and KDE 2.1.1.

This release provides the following fixes:

Security fixes:

KDEsu. The KDEsu which shipped with earlier releases of KDE 2
writes a (very) temporary but world-readable file with authentication
information. A local user can potentially abuse this behavior to gain
access to the X server and, if KDEsu is used to perform tasks that require
root-access, can result in comprimise of the root account.

Bug fixes:

kio_http. Fixed problems with "protocol for http://x.y.z died unexpectedly" and with proxy authentication with Konqueror.

For more information about the KDE 2.1 series, please see theKDE 2.1.1
press release and the KDE
2.1.1 Info Page, which is an evolving FAQ about the latest stable release.
Information on using anti-aliased fonts with KDE is availablehere.

Some distributors choose to provide binary packages of KDE for certain
versions of their distribution. Some of these binary packages for
kdelibs 2.1.2 will be available for free download underhttp://ftp.kde.org/stable/2.1.2/distribution/
or under the equivalent directory at one of the many KDE ftp servermirrors. Please note that the
KDE team is not responsible for these packages as they are provided by third
parties -- typically, but not always, the distributor of the relevant
distribution (if you have any questions, please read theKDE Binary Packages Policy).

kdelibs 2.1.2 requires qt-2.2.3, the free version of which is available
from the above locations usually under the name qt-x11-2.2.3, although
qt-2.2.4 or qt-2.3.0 is recommended (for anti-aliased fonts,
qt-2.3.0 and XFree 4.0.3 or newer is required).
KDE 2.1.2 will not work with versions of Qt older than 2.2.3.

Please check the servers periodically for pre-compiled packages for other
distributions. More binary packages may become available over the
coming days and weeks.

About KDE

KDE is an independent, collaborative project by hundreds of developers
worldwide to create a sophisticated, customizable and stable desktop environment
employing a component-based, network-transparent architecture.
KDE is working proof of the power of the Open Source "Bazaar-style" software
development model to create first-rate technologies on par with
and superior to even the most complex commercial software.

KDE and all its components are available for free under
Open Source licenses from the KDE server
and its mirrors and can
also be obtained on CD-ROM.
As a result of the dedicated efforts of hundreds of translators,
KDE is available in 34
languages and dialects. KDE includes the core KDE libraries, the core
desktop environment (includingKonqueror), developer packages
(including KDevelop), as well as the
over 100 applications from the other standard base KDE packages
(administration, games, graphics, multimedia, network, PIM and utilities).

Trademarks Notices.
KDE and K Desktop Environment are trademarks of KDE e.V.
Linux is a registered trademark of Linus Torvalds.
Unix is a registered trademark of The Open Group.
Trolltech and Qt are trademarks of Trolltech AS.
All other trademarks and copyrights referred to in this announcement are the property of their respective owners.

It's not a waste of time to fix the bugs. This is the sort of thing that makes KDE a stable, usable desktop for linux so it can help to enduce windows users to move accross.

Joe user won't change from microsoft if he thinks that the alternative is only trying to look good and not to atain stablility. Even though Windows is not as stable, the open source community has to try to dispell the inaccurate belief, among desktop users, that it is full of bugs. The KDE team are doing a good job of working towards this.

Great work! I didn't look at the security
aspect but konqueror works much better now.
It was my main browser before but sometimes
didn't work with a site. I suppose there
are still sites that don't work but a quick
test for a few hours didn't find any. KDE is
so cool.